Monday, June 30, 2025
Google search engine
HomeTechnologyCyber SecurityMicrosoft Entra account lockouts attributable to person token logging mishap

Microsoft Entra account lockouts attributable to person token logging mishap


Microsoft confirms that the weekend Entra account lockouts have been attributable to the invalidation of short-lived person refresh tokens that have been mistakenly logged into inner programs.

On Saturday morning, quite a few organizations reported that they started receiving Microsoft Entra alerts that accounts had leaked credentials, inflicting the accounts to be locked out robotically.

Impacted clients initially thought the account lockouts have been tied to the rollout of a brand new enterprise software referred to as “MACE Credential Revocation,” put in minutes earlier than the alerts have been issued.

Nevertheless, an admin for one of many impacted organizations shared an advisory despatched by Microsoft stating that the difficulty was attributable to the corporate mistakenly logging the impacted account’s person refresh tokens fairly than simply their metadata.

After realizing they logged precise account tokens, they started invalidating them, which by accident generated the alerts and lockouts.

“On Friday 4/18/25, Microsoft recognized that it was internally logging a subset of short-lived person refresh tokens for a small proportion of customers, whereas our normal logging course of is to solely log metadata about such tokens,” reads an advisory from Microsoft posted on Reddit.

“The interior logging concern was instantly corrected, and the group carried out a process to invalidate these tokens to guard clients.  As a part of the invalidation course of, we inadvertently generated alerts in Entra ID Safety indicating the person’s credentials might have been compromised.”

“These alerts have been despatched between 4/20/25 4AM UTC and 4/20/25 9AM UTC. We have now no indication of unauthorized entry to those tokens – and if we decide there have been any unauthorized entry, we are going to invoke our normal safety incident response and communication processes.”

Microsoft says impacted clients may give the “Verify Person Protected” suggestions in Microsoft Entra for the flagged person to revive entry to their accounts.

The corporate says they’ll publish a Put up Incident Overview (PIR) after the investigation is completed, which can be shared with all impacted clients.

BleepingComputer additionally contacted Microsoft on Saturday however has not but obtained a reply to our questions in regards to the incident.



Supply hyperlink

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments